Unclear Which setting a user changes to disallow unsandboxed commands is not confirmed.
What
The sandbox is a restricted environment that shell commands run inside, which limits what they can reach. Each tool Claude can use comes with a schema, a description of the inputs Claude is allowed to fill in. The Bash and PowerShell tools have an input called dangerouslyDisableSandbox, which asks to run a command outside the sandbox.
The schemas are now trimmed to match your sandbox settings:
dangerouslyDisableSandboxis removed from the Bash and PowerShell input schemas when the sandbox settings reportunsandboxedCommandsDisabled.run_in_backgroundis still removed separately from the Bash schema when background tasks are disabled.- For another schema, the same trimming also removes
run_in_backgroundand_simulatedSedEdit. - The setup that turns off both background tasks and unsandboxed commands is applied where the tool schemas are listed.
Before this release, the schemas kept dangerouslyDisableSandbox in these cases. It was only listed as an input that would be refused if Claude used it.
Why
If your setup does not allow commands to run outside the sandbox, Claude is no longer shown an option it cannot use. It therefore cannot try to escape the sandbox and then be refused.
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
The unsandboxed retry is an escape hatch for commands that fail inside the sandbox, such as tools that are incompatible with it. When the sandbox blocks a network connection, Claude Code names the denied host in the command's result, so Cl…sandboxing see the edit
"timeout": int | None, # Milliseconds. Foreground: capped at 600000 by default, higher values are clamped. With run_in_background (Claude Code v2.1.285 or later): the background time limit, 1800000 when omitted, capped at 7200000 unless ra…agent-sdk/python see the edit
* Changed background Bash and PowerShell commands to stop after a time limit (their `timeout` with `run_in_background`, default 30 min, max 2 h); Claude is notified when one is stoppedchangelog see the edit
Which setting a user changes to disallow unsandboxed commands is not confirmed.
Anthropic's documentation has since written up run_in_background, on Claude Code changelog.